697 karma · joined December 13, 2011
The new 2.x release of Facebook Container allows people to use "Log in with Facebook". To do so, it adds the site into the Facebook Container so sub-resources and 3rd-party cookies are available to the Facebook SDK js.
It warns the user before they enable this on any site.
Just to clear this up: The code for this is actually way simpler and sends no data to either Mozilla nor HIBP. To prevent Firefox from sending data update pings to HIBP, Firefox Monitor maintains a copy of publicly available HIBP breaches and their metadata [1] in the Firefox "Remote Settings" service. [2]
Using that data, Firefox simply checks for saved logins for breached sites where the saved password is older than the breach. [3]
[1] https://haveibeenpwned.com/api/v2/breaches [2] https://wiki.mozilla.org/Firefox/RemoteSettings [3] https://hg.mozilla.org/mozilla-central/file/6484c07ff8364991...
But future breach alerts will be sent to the Primary address. (If you select that in your preferences.)
* Sensitive Breaches * "Retired" Breaches * Spam Lists * Fabricated Breaches * non-Verified Breaches
https://github.com/mozilla/blurts-server/blob/master/hibp.js...
Note: We just released a "V2" of the site that allows you to add multiple email addresses to monitor, and (then) to have all your breach alerts sent to your single primary email address.
Watch this space: https://github.com/mozilla/blurts-addon/issues/142
;)
As mentioned in another comment, you can opt-out of the HIBP database here: https://haveibeenpwned.com/OptOut
I also filed https://github.com/mozilla/blurts-server/issues/466 to consider making this visible in the Monitor UI.
As mentioned in another comment, you can opt-out of the HIBP database here: https://haveibeenpwned.com/OptOut
I also filed https://github.com/mozilla/blurts-server/issues/466 to consider making this visible in the Monitor UI.
I certainly trust the MDN team to understand how to arrange their content to match their audience.
I also believe web developers should be more informed about the privacy & security issues of their work. The content you tried to add was verbose without any technical detail or links, and the MDN revision history isn't a great space for content discussion.
Have you tried filing a content bug? It's much easier to converse on bugzilla than thru edit battles.
https://bugzilla.mozilla.org/form.doc?bug_file_loc=https%3A/...
First-Party Isolation (FPI) did have the highest breakage scores: ~18-19% of users reported problems with it, and 9-10% of FPI users disabled the study.
Those are low relative numbers, but at entire-market scale, they are big absolute numbers. :/
https://blog.mozilla.org/data/2018/01/26/improving-privacy-w...
Cliqz has done some interesting research in this area of detecting (and stripping) unsafe data elements.
http://josepmpujol.net/public/papers/pujolTrackingTheTracker...
https://mitpress.mit.edu/books/obfuscation
Full of obfuscation tactics like that.
We close the previous tab and cancel the webRequest before it's sent to the site so none of the default cookies are sent.
"Converting" a tab from one container to another is actually a bit complicated, and there are open issues for it. :/
So ITP does nothing to protect a user who visits facebook.com every day. Which is most of Facebook's user-base.